@ceedaragents/release
Run a Cyrus release by publishing all packages to npm in the correct dependency order, updating changelogs, and creating git tags.
| name | release |
| description | Prepare, verify, publish, and finish a coordinated Cyrus CLI release. Use when a user asks to release Cyrus, publish cyrus-ai, run a CLI release, or perform the /release workflow. |
Release Cyrus
Run Cyrus releases through the trusted-publishing workflow. Do not publish workspace packages manually.
Required reference
Read apps/cli/RELEASING.md completely before taking release actions. Treat it
as the canonical operator guide and scripts/release-packages.mjs as the
canonical package list and dependency order.
Workflow
- Fetch
origin/main, start from current main, and preserve unrelated local changes. - Prepare the release on a branch:
- Move both changelogs' Unreleased entries into the new version.
- Set the same version in every manifest printed by
node scripts/release-packages.mjs list. - Run
pnpm installand commit any lockfile change. - Run the F1 release test-drive protocol and save its report with the
required
-release-v<version>.mdsuffix. - List every released
package@versioninCHANGELOG.md.
- Run
node scripts/release-packages.mjs validate <version>, then all checks required byapps/cli/RELEASING.md. Fix failures before continuing. - Commit, push, open the release PR, and merge it to
mainbefore dispatching the workflow. Never publish unmerged source or a non-main ref. - Dispatch
.github/workflows/release-cli.ymlfrommainin dry-run mode and monitor it through completion. - Only when the user has explicitly requested the live release, dispatch the
same exact version with
dry_run=false. Monitor it through npm publication, git tagging, and GitHub Release creation. - Independently verify the version on npm and run the published CLI's
--versioncommand. - Use the Linear integration to move every issue referenced by the version's
changelog section from
MergedUnreleasedtoReleasedMonitoring.
Safety
- Never add an npm token. Publishing must use GitHub Actions OIDC.
- Confirm every npm package trusts
cyrusagents/cyrusandrelease-cli.ymlbefore the first live workflow run. - A dry run does not authenticate to npm and does not prove registry writes.
- Never rerun a partially published version blindly. npm versions are immutable; inspect which packages landed and recover deliberately.
- Do not create or move a release tag until every package is published. The workflow owns tag and GitHub Release creation.
Loading...
Select a file to preview
Analyzing security...
Checking scan reports and verification data.
Bill of Materials
Everything this skill can do — files, network, commands, and more.